Cleartext storage of sensitive information in Windows Hello allows an authorized attacker to perform tampering locally.